Investment and trading scams
Fake platforms, clone firms and "advisers": who runs them, which entities received funds, and which other brands share the same operators.
Financial crime OSINT turns the traces fraudsters leave behind, such as domains, companies, phone numbers, payment details and social accounts, into names, networks and evidence. We investigate investment scams, impersonation, procurement and insider fraud for companies, insurers, banks and their lawyers.
Financial crime OSINT is the use of public and licensed sources to investigate fraud: who registered the domain, who directs the company that received the money, which other victims and fake brands share the same infrastructure, and where the proceeds went. OSINT-S identifies the people and networks behind a fraud and documents the evidence so your lawyers, the police or a regulator can act on it.
Reported fraud losses reached new highs in 2025, led by investment scams and business email compromise, and most insider fraud ran for a year before discovery.
Behind most of these losses sit repeatable patterns: the same registration agents, hosting, phone ranges and recipient companies reused across many victims. That reuse is what an open-source investigation exploits.
Six common case types. Each starts with what you already hold, such as emails, invoices, payment details or a website, and works outward.
Fake platforms, clone firms and "advisers": who runs them, which entities received funds, and which other brands share the same operators.
Spoofed suppliers and executives, look-alike domains and changed bank details, traced to the infrastructure and the holders of recipient accounts.
Shell suppliers, bid rigging and kickbacks: hidden links between vendors, employees and decision-makers.
Undisclosed companies, conflicts of interest and lifestyle evidence, supported by employee screening where it applies.
Counterparties that do not exist as claimed: borrowed registrations, stolen identities and fabricated track records.
The companies and people that receive and pass on fraud proceeds, mapped to support recovery and reporting.
Fraudsters reuse infrastructure. Each reused element, such as a domain registrant, phone number, photo or company officer, links one scheme to the next and eventually to a person.
A typical case begins with a handful of artifacts: a website, a few emails, an invoice with bank details, a phone number, perhaps a messaging handle. We expand each one. Domains lead to registration history, hosting, certificates and sibling sites. Recipient companies lead to directors, addresses and filing agents. Phone numbers and handles lead to accounts in other names. Photos of "advisers" lead to stock libraries or stolen profiles of real people.
The aim is a chart that connects the scheme to the people and companies who run or profit from it, with every link graded: confirmed by an independent record, likely, or only possible. Where the fraud ran through social platforms, we combine this with social media investigations; where funds left as cryptocurrency, with crypto investigations.
Different audiences need different evidence. We agree the destination at the start so the report fits it.
| Audience | What they need | What we provide |
|---|---|---|
| Police and prosecutors | A clear account of the offense, identified suspects, and evidence they can verify and obtain formally | Concise referral pack: timeline, suspects, linked entities, preserved captures and the records officers can request |
| Regulators | Firms or people acting without authorization, or failures in controls | Entity and individual profiles, links between clone firms, dated evidence of activity |
| Civil recovery lawyers | Defendants to sue, assets to freeze, and grounds for disclosure orders against banks or platforms | Defendant identification, asset tracing, and documented links that support applications |
| Insurers and boards | What happened, who is responsible, and whether controls failed | Findings report with confidence grading and recommendations |
Insurers handling fraud claims can see more on our page for insurance, and banks and payment firms on our page for financial services.
Report the fraud, call your bank, preserve everything, and do not confront the suspects. Speed matters most when money is still moving.
When fraud is reported quickly, money can sometimes be stopped. The FBI's Recovery Asset Team handled 3,900 incidents in 2025 through its Financial Fraud Kill Chain, with a 58% success rate and about $679 million frozen (FBI IC3 2025 report). That only works if the bank and the authorities hear about it in time.
So the first steps are yours: ask your bank to recall the payment, report to the police or IC3 in the US, keep the original emails with headers, invoices, chat logs and screenshots, and do not reply to the fraudster or warn suspected insiders. Brief us at the same time; we can start preserving the public side of the scheme, such as websites and accounts, before it disappears.
From your artifacts to identified people and a report shaped for its audience, with senior review before delivery.
Focused cases from 10 business days, lawful sources only, and a clear handover where police powers or court orders are needed.
A focused investigation into one scheme takes from 10 business days; complex, multi-country networks take up to about a month. Urgent work, for example before a freezing application, costs 50% more, and if we miss the agreed date, the fee goes down. Everything is confidential, under NDA where you need one.
We do not hack fraudsters back, pose as victims to extract information, or buy leaked data. Bank account holders and transaction records are obtained by police or by your lawyers through disclosure orders, not by us. Personal data is handled for a defined purpose and in proportion to it under the GDPR and UK GDPR (GDPR). If the main question is whether your onboarding controls work, KYC and AML support is the better fit. Fraud work is one of the OSINT services for fraud and compliance teams we run as one team.
Focused versions of fraud investigations for specific subjects, deals and situations.
Fake trading platforms and clone firms traced to the companies, payment routes and people behind them, with evidence for lawyers and police.
Read more →Diverted payments traced: whose mailbox was used, the campaign behind it, the recipient account and companies, with evidence for banks and insurers.
Read more →Fake vendors, kickbacks, hidden conflicts of interest and bid rigging: links between staff, suppliers and bidders found and documented.
Read more →Send what you have: emails, invoices, payment details, websites and the outcome you need. We reply with a scope, a timeline and a fixed quote.
Often, yes. We trace the look-alike domain's registration history, hosting and sibling domains, and investigate the company or person named on the receiving account: officers, addresses, filing agents and links to other schemes. The result is a set of identified people and entities graded by confidence, which your lawyers can use for disclosure orders and the police for a referral. Report the payment to your bank at once; speed matters for recall.
Usually. Platforms like this reuse templates, hosting, payment processors, support numbers and company agents across many brands. We map those links, identify the companies and people behind them, and look for regulator warnings, complaints and other victims. That helps a lawyer decide whether a claim or group action is realistic. If you were contacted by someone offering to recover your money for a fee, treat it as a likely second scam.
We look for connections between the manager and the supplier in public records: directorships and shareholdings, relatives as officers, shared addresses, phones, domains and accountants, and changes made around contract awards. We work only from outside sources, so nothing alerts him. Findings are graded so your HR and legal teams know what is confirmed before an interview or disciplinary step. Internal records such as emails remain for your own investigators.
The report sets out what happened, who was involved, how they are linked and how confident we are in each finding, with a source record for every fact: where it came from and when it was captured. Copies are kept. It is written so lawyers can adapt it into a witness statement, and the analyst can explain the method if needed. Agree the audience at the start so the format fits.
Yes. Automated screening clears most alerts; the rest need someone to look at who the customer really is, who controls the business and where the money comes from. We investigate escalated cases one by one with ownership, adverse media, sanctions links and network analysis, and return a written finding your team can file. For ongoing exposure, we can also monitor high-risk names on our analyst-reviewed platform, which updates hourly.
A focused investigation into a handful of vendors takes from 10 business days. We check whether each vendor exists as claimed, who owns and runs it, and how it links to the former employee. If the link is confirmed, we can move straight into asset tracing so your lawyers know what is recoverable and where. Recovery itself runs through civil claims or the police; we support both with evidence.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.